PhishShield

Phishing Simulation

20+ realistic attack templates across every vector

Cyber Essentials

NCSC-backed certification against common cyber threats

Threat Analytics

Real-time human risk intelligence dashboard

Compliance Reports

Board-ready audit documentation and audit trails

View all platform features →

Enterprise

Full security suite with dedicated support and SLAs

Financial Services

FCA, PCI-DSS and BEC fraud defence for finance teams

Education

DfE-aligned cyber security for schools and MATs

Healthcare

DSPT-aligned phishing defence for NHS and private care

View all solutions →

Documentation

Setup guides, API reference, and integrations

Cyber News

Live threat intelligence from Krebs, NCSC, Bleeping Computer and more

Case Studies

Real customer outcomes and measurable ROI data

Threat Intelligence

Latest phishing campaign TTPs and analysis

Explore all resources →
Pricing

Campaign login

Admin dashboard

Training portal

Employee learning

Get started

// UK Government-backed certification

Cyber Essentials
readiness guide.

Understand the five controls, track your progress with our free checklist, and approach an accredited assessor when you're ready.

PhishShield is not a Cyber Essentials certification body. We provide a readiness checklist to help you prepare. Official certificates are issued exclusively by IASME and its licensed assessors on behalf of the NCSC.

Use the free checklistThe five controls →

~80%

of attacks preventable with CE controls

Mandatory

for central government contracts

£25k

free cyber insurance for eligible UK orgs

// The framework

Five controls. Baseline protection.

01

Firewalls

Ensure only authorised traffic can reach your network — including devices used away from the office.

02

Secure Configuration

Remove default passwords, disable unnecessary accounts and services, and enable full-disk encryption on laptops.

03

User Access Control

Apply least-privilege principles. Only administrators should have admin accounts. MFA required for cloud services.

04

Malware Protection

Anti-malware on all devices, email filtering, and application allow-listing where appropriate.

05

Patch Management

Critical security patches applied within 14 days. No end-of-life software in use.

// Where we fit in

How PhishShield supports your CE journey.

01PREPARATION

Readiness checklist

A detailed breakdown of every CE sub-requirement (v3.3) so you can self-assess before paying for a formal assessment.

02EVIDENCE

Phishing simulations

Measurable evidence that staff can identify phishing — directly relevant to the User Access Control and Malware Protection controls.

03DOCUMENTATION

Risk reporting

Click-through rates, department breakdowns, and trend data provide documentation your assessor will find useful.

// Next step

Find a certified assessor.

IASME Consortium

The main NCSC-approved certification body for CE. Use their directory to find a local licensed assessor.

Find an IASME assessor

NCSC Cyber Essentials

The official NCSC guidance, including the current requirements document (v3.3) and FAQs.

NCSC official guidance

PhishShield is not affiliated with IASME or the NCSC. These links are provided for your convenience.

// FAQ

Common questions.

What is Cyber Essentials?

Cyber Essentials is a UK government-backed certification scheme, developed by the National Cyber Security Centre (NCSC), that helps organisations protect against the most common cyber threats. It covers five technical controls.

Who issues Cyber Essentials certificates?

Certificates are only issued by NCSC-approved certification bodies — currently IASME and its licensed assessors. PhishShield is not a certification body and does not issue certificates. We provide a readiness checklist to help you prepare before approaching an assessor.

Do I need Cyber Essentials for government contracts?

Yes. Since October 2014, all suppliers bidding for central government contracts involving the handling of personal information or sensitive data must hold a valid Cyber Essentials certificate.

What's the difference between Cyber Essentials and CE Plus?

Cyber Essentials is a self-assessed questionnaire reviewed by an assessor. Cyber Essentials Plus adds hands-on technical verification by an accredited assessor, including scanning and testing of your systems.

Does CE certification include cyber insurance?

Cyber Essentials certification makes eligible UK organisations (turnover under £20M) eligible for free cyber liability insurance up to £25,000 through IASME. This is provided by the certification body, not by PhishShield.

How does PhishShield support Cyber Essentials?

Phishing simulations provide measurable evidence that your staff can identify and report phishing attempts — directly supporting the User Access Control and Malware Protection controls. This evidence can complement your certification application, but PhishShield does not provide certification itself.

// Get started

Start preparing
for Cyber Essentials.

Use our free readiness checklist inside the PhishShield dashboard to understand exactly where your organisation stands before you contact an assessor.

Open the checklist

Free with all plans · Certification issued by IASME assessors only

PhishShield

Enterprise phishing simulation and security awareness training for modern organisations. Built by security people, for security teams.

SOC 2 Type IIISO 27001GDPR

Product

  • Features
  • Template Library
  • Pricing
  • Status

Company

  • About
  • Testimonials
  • Cyber News
  • Careers
  • Contact Sales
  • Enterprise

Legal

  • Privacy Policy
  • Terms of Service
  • GDPR
  • Security

© 2026 PhishShield, Inc. All rights reserved.

For authorised security awareness testing only.